ZeroHour

CVE-2026-76442

large

Unauthenticated Denial-of-Service in Cisco Secure Email Gateway and Web Manager

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-76442 groups multiple internally discovered vulnerabilities in Cisco Secure Email Gateway (formerly Email Security Appliance) and Cisco Secure Email and Web Manager (formerly Security Management Appliance) that stem from improper validation of a specified quantity in input (CWE-1284 pillar). The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) indicates the flaws are exploitable remotely over the network with no authentication, no user interaction, and low attack complexity, with impact limited to availability. An unauthenticated attacker can send specially crafted input that improperly consumes or crashes the affected service, causing denial of service and disrupting inbound and outbound mail flow for organizations that rely on these gateways. The issues were found during Cisco's proactive internal security review and are addressed in Cisco's software hardening releases. There is no known public proof-of-concept, no evidence of in-the-wild exploitation, and the CVE is not in CISA's KEV catalog.

What to do: Upgrade Cisco Secure Email Gateway and Cisco Secure Email and Web Manager to the latest fixed builds listed in Cisco's PSIRT advisory, since no specific version numbers were provided in the source data. Restrict management and web administration interfaces to trusted internal networks and verify normal SMTP processing and mail queue drainage after patching. Until patched, monitor appliance CPU, memory, and service availability for signs of resource exhaustion or crashes.

Affected
Cisco Secure Email Gateway (formerly Email Security Appliance)Affected version ranges not enumerated in the source data; fixes delivered in Cisco software hardening releases referenced by the advisory
Cisco Secure Email and Web Manager (formerly Security Management Appliance)Affected version ranges not enumerated in the source data; fixes delivered in Cisco software hardening releases referenced by the advisory
Estimated exposure
large≈tens of thousands (10k–100k) of internet-exposed appliances, clearly an estimate — Secure Email Gateway appliances are typically internet-facing on TCP/25 as MX targets, and public scan services have historically shown tens of thousands of exposed Cisco AsyncOS-based hosts, though exact current counts are unavailable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76442 are related to issues with improper validation of specified quantity in input that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-1284.

Weakness
CWE-1284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.